It should be obvious, that you should secure any website with an SSL certificate. There's neither an excuse nor a valid reason for it. Ok, there's one theoretical exception I would accept.
If your use case is different you shuold use an SSL certificate. I'm using 'Let`s encrypt' service for my private environment. Using it with Windows IIS is pretty easy too as you will see in my latest blog post. It requires:
READ MORE: here.